Problem: Anyone can sync with TSN nodes
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
- issue の種類
- バグ
- 明瞭さ
- 説明が足りない
- 活発さ
- 停滞
- 技術スタック
- go
調査の方向性
The issue names no files, tests, or entry points. Start by tracing how TSN/Kwil nodes authorize peer access and synchronization, then confirm the chosen VPN or validator-only approach with maintainers. Done means unauthorized peers cannot populate a read-only node with chain data and the operational guidance reflects the decision.
索引モデルが issue の本文から書いたものです。
説明
What is happening:
- before node operators, our p2p port was closed.
- with node operators, we need to give nodes p2p access
- currently, anyone with p2p access can say, "I want to be a read-only node of TSN chain" even if they are not validators
- this means, when they connect, their DB is filled with all current data, without needing an approval
Solutions:
- make VPN part of our infra, guide node operators to connect through it
- ask the kwil team to add an option that disallows syncing without being a validator (1 week work, Brennan said). This makes the read-only nodes not possible, correct?
- keep it insecure for now, relying on the obscurity that our
tsn-node-operatorscan remain private for now, and people won't immediately know the servers, genesis file, software, etc(@brennanjl all correct?)
I'd vote for 2, or incrementally 3, then 2. Reasons:
- onboarding won't be blocked
1makes the infra + onboarding significantly more complex3seems ok with Cameron's decision about priority- VPN would also be a temporary solution, requiring more trust in operators, etc
Originally posted by @outerlook in https://github.com/truflation/tsn/issues/457#issuecomment-2288518928
@markholdex
@outerlook let's go with 3 now until 2 is not ready. Isolate no 2 in a separate problem, please.
@brennanjl What are the limitations or negative consequences of option 2? When can you put it on your roadmap and when can we see it ready?
- 主要言語
- Go
- スター
- 7
- フォーク
- 3
- 平均マージ
- 3時間 2分
- マージ済み PR(30日)
- 13
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
trufnetwork/node のほかの issue
-
type: goal
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
trufnetwork/node#1436 ·
メンテナーはふだん 1 日以内に返信
-
Problem: settlement can't tell a capture was taken too early対応中かも @MicBun が 8 日前に担当しました。 オープン
trufnetwork/node#1435 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
Goal: SDK call for market volume over a time period対応中かも @vinarmani が 9 日前に担当しました。 オープン
trufnetwork/node#1429 · コメント 2 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
trufnetwork/node#1313 · コメント 2 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
trufnetwork/node#1200 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
trufnetwork/node の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 65/100
521xueweihan/HelloGitHub#3789 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 12 日以内に返信
-
stage-fail
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
siyuan-note/bazaar#2282 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
openshift/kube-compare#307 ·
メンテナーはふだん 1 日以内に返信